Black Kite counted 1,183 publicly disclosed ransomware victims in manufacturing in the first seven months of 2026, up 39.7% on the same period last year and already more than in all of 2023 or 2024, and its manufacturing report has ranked the sector the most-attacked industry for five consecutive years. Nearly half of this year’s victims were hit by groups absent from the data in 2023 and 2024, some of them rebrands, so newcomers are arriving with the playbook already learned.Black Kite’s research chief describes that playbook plainly: one attack can stop production, and every hour of downtime strengthens the attacker’s hand, which makes time the thing the attacker is really holding.In most manufacturing, the clock that matters is how long the business can absorb a stopped line. In food and beverage, the clock is printed on the product, and attackers have noticed: the Food and Ag-ISAC counted 227 ransomware incidents against food and agriculture through July, up 62% on the same period last year.This summer’s Fairlife incident looked like a disaster in the headlines, and why it wasn’t one tells food manufacturers more. What follows is a composite of how these events tend to run, not any one company’s timeline, with the facts Coca-Cola disclosed about Fairlife as the bookends. T+0: the alert is in ITRansomware is confirmed on enterprise hosts, and nothing on the plant floor has changed. Lines are running, products are moving, and the first question on the incident bridge is the obvious one: what else did they touch?On July 16, Coca-Cola disclosed in an SEC filing that Fairlife had identified unauthorized access to a portion of its systems, “including its production-related systems,” in connection with a ransomware event. Production was suspended at all four US plants, while Canadian production was not affected and product quality and safety were not impacted. Coca-Cola has not said whether anything on the plant floor was reached, which is the shape of most public disclosures. T+2 hours: the question nobody can answerBetween the office and the line sits a layer both sides trust: the MES, recipe management, batch records, quality and lab systems, label printing, and the warehouse system that decides what ships. Every one of them is a Windows or Linux host, and a decade of Industry 4.0 investment connected them to the plant network on purpose.So the bridge question becomes: from the compromised segment, what can actually open a connection to an HMI, a line-side server, a controller, or the systems that write the batch record?In most plants the honest answer at hour two is “we don’t know.” Oscar Calderon, IBM’s OT cybersecurity GRC leader, told Industrial Cyber in September that he has seen production stop when teams could no longer trust control systems, batch records, or quality data, with the equipment itself working fine. If the systems that write batch records and release holds might be reachable, stopping the line is the right call, made with almost no information. T+1 shift: the ledger startsThis is where food and beverage separates from the rest of manufacturing, because everything in the plant was on a clock before the alert.What is waitingWhat it is waiting onHow long it hasRaw inputs in receiving and silosThe line to restart. Raw milk, livestock and crops keep arriving, so lost days become destroyed raw material (Stuart King of AnzenOT, speaking to Industrial Cyber)Hours to a dayProduct in processA sequenced restart. “There is no such thing as a short outage” (King): product stuck mid-line and spoiling, systems reset, trucks at the dockThe shiftFinished goods in cold storageA release decision that needs trusted records. If the HACCP records for a production window are unverifiable, everything made in that window is presumptively suspect (King)Every day offline is a day off the shelf life you sellRetail commitmentsTrucks and shelves. Large retailers now treat cybersecurity and traceability as conditions of doing business (Calderon)Days, and the shortfall is on a shelf in public viewTrust in the systems that feed the lineSomeone to prove the attacker never reached themIndefinite, until provenThe attacker is counting on that last row, and the four above it are why a food plant was chosen in the first place. T+3 days: the negotiation is about datesBy day three the encrypted files matter less than they seem, because backups exist for those. There is usually a data-theft claim too; in Fairlife’s case the Anubis group claimed a terabyte, and Coca-Cola confirmed that certain data was taken. In a food plant, the leverage that compounds is whatever goes out of date while the plant proves a negative.Jaguar Land Rover’s September 2025 attack halted UK production for about five weeks, and on September 7 this year JLR announced about 4,000 job cuts amid the fallout. That is brutal, but a car does not expire in five weeks, while fresh milk cannot sit anywhere for one. T+11 days: most production resumesOn July 27, Coca-Cola said Fairlife had resumed the majority of production at its four US facilities and that retail availability had been “largely unimpacted, due to the availability of existing inventory.” It did not expect a material impact, and the next day CEO Henrique Braun told analysts supply and consumer service had not been affected.From the attacker’s side, that is a strange result: eleven days between Coca-Cola’s first disclosure and its restoration update, at a brand Coca-Cola says grew from about $10 million to nearly $4 billion in retail value, and the ledger never reached the shelf.That outcome was engineered into the product. Ultra-filtration and higher-temperature pasteurization give Fairlife’s milk a far longer unopened shelf life than conventional milk, and its protein shakes are shelf-stable. Enough finished product already in the channel, and a product built to sit on a shelf, gave Fairlife what most food manufacturers lack, which is runway measured in days. It also shaped the response: by Anubis’s own account, Fairlife reported the incident rather than follow the instructions left on its network, a choice that is far easier to make while the shelves are still full.Now run the same eleven days at a fresh-milk bottler, a protein plant, a produce packer, or a bakery, where no inventory outlasts the outage. King made the point to Industrial Cyber: a dairy or protein plant with a difficult, sequenced restart takes days to come back regardless of how sophisticated the attacker was. Those are plants that cannot buy a shift, let alone eleven days.In most of these incidents, the length of the outage is not set by the malware. It is set at hour two, when the honest answer to “what can the compromised segment reach?” is “we don’t know.”Same eleven days. The plant stops on the top clock and pays on the bottom one. Recovery phases are illustrative, not Fairlife’s disclosed timeline. What would have to be true at T+2 hoursA plant that cannot buy runway with inventory has one lever left, which is to shorten the outage. The fastest restarts will come from plants that can answer three questions before the incident, whatever the state of their backups.Reach. From a compromised host in IT, or in a supplier’s network, what on the plant floor can be connected to at all? If the answer is “most of it,” the shutdown decision was made years ago when the network was designed, and the incident is only collecting on it. Food and Ag-ISAC’s Jonathan Braley notes that many OT compromises start in corporate IT and move laterally through weak segmentation.Dependency. Which production systems actually need a path to enterprise IT to keep running, and which have one only because the network was built flat? And where do the systems that write batch records and release holds actually live?Proof. Can you show, from records you already keep, what a given host has talked to in the last 30 days, so “we don’t know” becomes “we know it never reached the line”?Four controls make those answers short.Segment every device. Zscaler Zero Trust Device Segmentation puts every production asset – controller, HMI, line-side server, vision system, and the MES, batch, and historian servers the line depends on – in a network of one, with no agents to install, no upgrades, and no downtime. A compromised host in IT gets no route to the line, which gives the reach question a one-word answer.Broker access instead of extending the network. OEM technicians, integrators, and your own engineers reach a specific controller for a specific session through Zscaler Privileged Remote Access, with no open RDP, SSH, or VNC ports on the plant, no network path between user and asset, and every session recorded, so the supplier’s network never becomes an extension of yours.Let the policy be the dependency map. When every allowed IT-to-plant flow is a policy rather than an accident of addressing, the dependency list is the policy itself, and it exists before the incident, which is when the bridge needs it. Eaton has taken this model across more than 100 manufacturing facilities.Keep the flow record. The same platform discovers and classifies every device on the plant network and records the flows between them, so the proof question is answered from data collected before the incident.Ransomware may still land, but when the plant’s dependencies sit inside a boundary you can prove, it lands in IT, the line keeps running, and the restart conversation is about the office. If batch records and release systems still live on the enterprise side, the dependency question is telling you to bring them inside first. Once they are, the ledger does not have to start, whether or not you have eleven days of inventory in the cooler.If you want to know what your own plants would answer at hour two, we run OT architecture workshops that start from your line-side dependencies and work outward: request an OT architecture workshop.  Or hear from our customers directly on how they are leveraging Zscaler OT Security solutions in their own environments.  

​[#item_full_content] Black Kite counted 1,183 publicly disclosed ransomware victims in manufacturing in the first seven months of 2026, up 39.7% on the same period last year and already more than in all of 2023 or 2024, and its manufacturing report has ranked the sector the most-attacked industry for five consecutive years. Nearly half of this year’s victims were hit by groups absent from the data in 2023 and 2024, some of them rebrands, so newcomers are arriving with the playbook already learned.Black Kite’s research chief describes that playbook plainly: one attack can stop production, and every hour of downtime strengthens the attacker’s hand, which makes time the thing the attacker is really holding.In most manufacturing, the clock that matters is how long the business can absorb a stopped line. In food and beverage, the clock is printed on the product, and attackers have noticed: the Food and Ag-ISAC counted 227 ransomware incidents against food and agriculture through July, up 62% on the same period last year.This summer’s Fairlife incident looked like a disaster in the headlines, and why it wasn’t one tells food manufacturers more. What follows is a composite of how these events tend to run, not any one company’s timeline, with the facts Coca-Cola disclosed about Fairlife as the bookends. T+0: the alert is in ITRansomware is confirmed on enterprise hosts, and nothing on the plant floor has changed. Lines are running, products are moving, and the first question on the incident bridge is the obvious one: what else did they touch?On July 16, Coca-Cola disclosed in an SEC filing that Fairlife had identified unauthorized access to a portion of its systems, “including its production-related systems,” in connection with a ransomware event. Production was suspended at all four US plants, while Canadian production was not affected and product quality and safety were not impacted. Coca-Cola has not said whether anything on the plant floor was reached, which is the shape of most public disclosures. T+2 hours: the question nobody can answerBetween the office and the line sits a layer both sides trust: the MES, recipe management, batch records, quality and lab systems, label printing, and the warehouse system that decides what ships. Every one of them is a Windows or Linux host, and a decade of Industry 4.0 investment connected them to the plant network on purpose.So the bridge question becomes: from the compromised segment, what can actually open a connection to an HMI, a line-side server, a controller, or the systems that write the batch record?In most plants the honest answer at hour two is “we don’t know.” Oscar Calderon, IBM’s OT cybersecurity GRC leader, told Industrial Cyber in September that he has seen production stop when teams could no longer trust control systems, batch records, or quality data, with the equipment itself working fine. If the systems that write batch records and release holds might be reachable, stopping the line is the right call, made with almost no information. T+1 shift: the ledger startsThis is where food and beverage separates from the rest of manufacturing, because everything in the plant was on a clock before the alert.What is waitingWhat it is waiting onHow long it hasRaw inputs in receiving and silosThe line to restart. Raw milk, livestock and crops keep arriving, so lost days become destroyed raw material (Stuart King of AnzenOT, speaking to Industrial Cyber)Hours to a dayProduct in processA sequenced restart. “There is no such thing as a short outage” (King): product stuck mid-line and spoiling, systems reset, trucks at the dockThe shiftFinished goods in cold storageA release decision that needs trusted records. If the HACCP records for a production window are unverifiable, everything made in that window is presumptively suspect (King)Every day offline is a day off the shelf life you sellRetail commitmentsTrucks and shelves. Large retailers now treat cybersecurity and traceability as conditions of doing business (Calderon)Days, and the shortfall is on a shelf in public viewTrust in the systems that feed the lineSomeone to prove the attacker never reached themIndefinite, until provenThe attacker is counting on that last row, and the four above it are why a food plant was chosen in the first place. T+3 days: the negotiation is about datesBy day three the encrypted files matter less than they seem, because backups exist for those. There is usually a data-theft claim too; in Fairlife’s case the Anubis group claimed a terabyte, and Coca-Cola confirmed that certain data was taken. In a food plant, the leverage that compounds is whatever goes out of date while the plant proves a negative.Jaguar Land Rover’s September 2025 attack halted UK production for about five weeks, and on September 7 this year JLR announced about 4,000 job cuts amid the fallout. That is brutal, but a car does not expire in five weeks, while fresh milk cannot sit anywhere for one. T+11 days: most production resumesOn July 27, Coca-Cola said Fairlife had resumed the majority of production at its four US facilities and that retail availability had been “largely unimpacted, due to the availability of existing inventory.” It did not expect a material impact, and the next day CEO Henrique Braun told analysts supply and consumer service had not been affected.From the attacker’s side, that is a strange result: eleven days between Coca-Cola’s first disclosure and its restoration update, at a brand Coca-Cola says grew from about $10 million to nearly $4 billion in retail value, and the ledger never reached the shelf.That outcome was engineered into the product. Ultra-filtration and higher-temperature pasteurization give Fairlife’s milk a far longer unopened shelf life than conventional milk, and its protein shakes are shelf-stable. Enough finished product already in the channel, and a product built to sit on a shelf, gave Fairlife what most food manufacturers lack, which is runway measured in days. It also shaped the response: by Anubis’s own account, Fairlife reported the incident rather than follow the instructions left on its network, a choice that is far easier to make while the shelves are still full.Now run the same eleven days at a fresh-milk bottler, a protein plant, a produce packer, or a bakery, where no inventory outlasts the outage. King made the point to Industrial Cyber: a dairy or protein plant with a difficult, sequenced restart takes days to come back regardless of how sophisticated the attacker was. Those are plants that cannot buy a shift, let alone eleven days.In most of these incidents, the length of the outage is not set by the malware. It is set at hour two, when the honest answer to “what can the compromised segment reach?” is “we don’t know.”Same eleven days. The plant stops on the top clock and pays on the bottom one. Recovery phases are illustrative, not Fairlife’s disclosed timeline. What would have to be true at T+2 hoursA plant that cannot buy runway with inventory has one lever left, which is to shorten the outage. The fastest restarts will come from plants that can answer three questions before the incident, whatever the state of their backups.Reach. From a compromised host in IT, or in a supplier’s network, what on the plant floor can be connected to at all? If the answer is “most of it,” the shutdown decision was made years ago when the network was designed, and the incident is only collecting on it. Food and Ag-ISAC’s Jonathan Braley notes that many OT compromises start in corporate IT and move laterally through weak segmentation.Dependency. Which production systems actually need a path to enterprise IT to keep running, and which have one only because the network was built flat? And where do the systems that write batch records and release holds actually live?Proof. Can you show, from records you already keep, what a given host has talked to in the last 30 days, so “we don’t know” becomes “we know it never reached the line”?Four controls make those answers short.Segment every device. Zscaler Zero Trust Device Segmentation puts every production asset – controller, HMI, line-side server, vision system, and the MES, batch, and historian servers the line depends on – in a network of one, with no agents to install, no upgrades, and no downtime. A compromised host in IT gets no route to the line, which gives the reach question a one-word answer.Broker access instead of extending the network. OEM technicians, integrators, and your own engineers reach a specific controller for a specific session through Zscaler Privileged Remote Access, with no open RDP, SSH, or VNC ports on the plant, no network path between user and asset, and every session recorded, so the supplier’s network never becomes an extension of yours.Let the policy be the dependency map. When every allowed IT-to-plant flow is a policy rather than an accident of addressing, the dependency list is the policy itself, and it exists before the incident, which is when the bridge needs it. Eaton has taken this model across more than 100 manufacturing facilities.Keep the flow record. The same platform discovers and classifies every device on the plant network and records the flows between them, so the proof question is answered from data collected before the incident.Ransomware may still land, but when the plant’s dependencies sit inside a boundary you can prove, it lands in IT, the line keeps running, and the restart conversation is about the office. If batch records and release systems still live on the enterprise side, the dependency question is telling you to bring them inside first. Once they are, the ledger does not have to start, whether or not you have eleven days of inventory in the cooler.If you want to know what your own plants would answer at hour two, we run OT architecture workshops that start from your line-side dependencies and work outward: request an OT architecture workshop.  Or hear from our customers directly on how they are leveraging Zscaler OT Security solutions in their own environments.